Hackers Exploit Leaked Shellter License to Distribute Lumma Stealer and SectopRAT Malware

Published:

spot_img

Hackers Exploit Shellter Tool to Distribute Malware

In a troubling trend within the cybersecurity realm, threat actors have begun leveraging Shellter, a widely used red teaming tool, to deploy stealer malware. This misuse emphasizes the ongoing challenges in safeguarding digital tools intended for ethical hacking and security testing.

The Issue at Hand

The Shellter Project recently revealed that a leak from a company that purchased Shellter Elite licenses has resulted in the weaponization of their software. This breach has allowed malicious actors to employ the tool for infostealer campaigns. To address the situation, the Shellter Project Team has issued an update designed to mitigate these vulnerabilities.

Despite their thorough vetting process, which had successfully prevented similar incidents since the launch of Shellter Pro Plus in February 2023, the team acknowledged the unfortunate circumstances of this case. Their statement reflects a deep concern for the misuse of tools intended for legitimate security practices.

Rise of Infostealer Campaigns

This situation has garnered attention, particularly following a report from Elastic Security Labs detailing how this powerful evasion framework has been misused since April 2025. Cybercriminals have been employing Shellter to distribute malware variants such as Lumma Stealer, Rhadamanthys Stealer, and SectopRAT, highlighting a new wave of financially motivated campaigns exploiting the shellcode capabilities.

The malicious efforts identified by Elastic include the packaging of payloads utilizing Shellter Elite version 11.0. The version was officially released on April 16, 2025, marking a significant escalation in the misuse of legitimate security software.

How Shellter Works

Shellter is renowned for its robustness, providing offensive security teams with the capability to bypass antivirus and endpoint detection systems. This tool’s efficacy relies on self-modifying shellcode and polymorphic obfuscation, which allows malware to embed itself into benign applications.

As noted by the Shellter Project, this sophisticated combination of legitimate code and obfuscation techniques enables malware to avoid detection from traditional security measures. In essence, it creates a façade that masks malicious intent, making it increasingly difficult for security systems to identify threats.

Tactics Used by Cybercriminals

Some of the malicious campaigns have reportedly started using this tool after its circulation on cybercrime forums. In mid-May, following the sale of Shellter version 11.0, threat actors began disseminating malware using targeted lures. These lures often attract unsuspecting users, particularly content creators interested in sponsorship opportunities or gaming modifications.

In contrast, the distribution of Lumma Stealer malware has been traced back to links hosted on MediaFire, marking a strategic approach to maximizing reach and effectiveness. By sidestepping direct downloads, cybercriminals enhance their chances of evading detection from security software.

A Broader Context of Cybersecurity Challenges

The trend of legitimate security products falling into the hands of malicious users is not new; cracked versions of tools like Cobalt Strike and Brute Ratel C4 have similarly found their way into the arsenal of cybercriminals. This history raises concerns that Shellter could follow a comparable trajectory, further intensifying the ongoing battle against cybercrime.

Moreover, the Shellter Project has expressed dissatisfaction with Elastic’s handling of the situation, accusing them of prioritizing publicity over the seriousness of public safety concerns. The project criticized Elastic for failing to notify them promptly about the exploitation, calling their actions reckless.

Conclusion

As cybersecurity continues to evolve, the repurposing of legitimate tools poses significant risks. With the rising threats from infostealer campaigns leveraging sophisticated techniques, it’s vital for both the security community and software developers to stay vigilant. Continuous monitoring and updates of security tools are crucial to combating the ever-evolving landscape of cyber threats.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...